1

Senior Vulnerability Analyst Jobs (NOW HIRING)

Senior Specialist Job Specialty: Cyber Security What You'll Do The Vulnerability Analyst is responsible for analyzing key data streams and interpreting threats, vulnerabilities, impacts, and ...

The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by identifying, analyzing, and prioritizing vulnerabilities and security risks across enterprise, cloud, and ...

... by senior security staff. * Monitor and analyze vulnerability and threat intelligence from government and commercial sources, including CISA KEV (Known Exploited Vulnerabilities) catalog, NVD, US ...

The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by identifying, analyzing, and prioritizing vulnerabilities and security risks across enterprise, cloud, and ...

... by senior security staff. * Monitor and analyze vulnerability and threat intelligence from government and commercial sources, including CISA KEV (Known Exploited Vulnerabilities) catalog, NVD, US ...

The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by identifying, analyzing, and prioritizing vulnerabilities and security risks across enterprise, cloud, and ...

Senior Vulnerability Researcher

Herndon, VA · Remote

$165K - $200K/yr

... a Senior Vulnerability Researcher to help us continue pushing boundaries. If you're passionate ... Analyze the effects of vulnerabilities on mission outcomes and operational effectiveness. * Compare ...

Senior Vulnerability Engineer

$117K - $160K/yr

About the Job As a Senior Vulnerability Engineer, you will design, build, and scale systems for ... Create dashboards and analytics to track vulnerability exposure, remediation SLAs, and risk trends

Serves as a senior technical leader within the Security Operations Center (SOC), responsible for ... The Vulnerability Analyst reports directly to the Security Operations Center (SOC) Manager. About ...

Senior Vulnerability Researcher Battelle delivers when others can't. We conduct research and ... Concolic analysis research and implementation * Experience emulating embedded platforms for live ...

Senior Vulnerability Researcher Battelle delivers when others can't. We conduct research and ... Concolic analysis research and implementation * Experience emulating embedded platforms for live ...

Showing results 21-40

Senior Vulnerability Analyst information

See salary details

$48.5K

$102.5K

$130.5K

How much do senior vulnerability analyst jobs pay per year?

As of Aug 11, 2026, the average yearly pay for senior vulnerability analyst in the United States is $102,527.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,000.00 and $116,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a senior vulnerability analyst, and why are they important?

To thrive as a Senior Vulnerability Analyst, you need deep knowledge of cybersecurity principles, vulnerability assessment methodologies, and a solid background in information technology, often supported by certifications like CISSP, CEH, or OSCP. Expertise with vulnerability scanning tools (e.g., Nessus, Qualys), penetration testing frameworks, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this role. These skills ensure accurate identification and remediation of security weaknesses, protecting organizational assets from evolving cyber threats.

What is the difference between Senior Vulnerability Analyst vs Vulnerability Analyst?

AspectSenior Vulnerability AnalystVulnerability Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CEH
ExperienceTypically 3+ years in cybersecurity rolesEntry to 2 years in vulnerability assessment
Work EnvironmentSecurity teams, IT departments, consulting firmsIT teams, security operations centers, consulting firms
ResponsibilitiesLeading vulnerability scans, mentoring, reportingConducting scans, identifying vulnerabilities, basic reporting

The main difference between a Senior Vulnerability Analyst and a Vulnerability Analyst lies in experience, responsibilities, and leadership. Senior analysts typically have more experience, handle complex assessments, and mentor junior staff, whereas vulnerability analysts focus on executing scans and identifying vulnerabilities. Both roles are essential in cybersecurity teams and often work in similar environments.

How does a senior vulnerability analyst typically collaborate with other teams to address security risks?

As a Senior Vulnerability Analyst, you will frequently work alongside IT, DevOps, and incident response teams to identify, prioritize, and remediate security vulnerabilities. Effective communication is key, as you'll need to translate complex technical findings into actionable recommendations for both technical and non-technical stakeholders. Regular meetings, vulnerability review sessions, and cross-team planning are common, ensuring that remediation efforts align with organizational priorities and compliance requirements. This collaborative approach not only strengthens the organization’s security posture but also fosters ongoing professional growth and knowledge sharing.

What does a senior vulnerability analyst do?

A Senior Vulnerability Analyst is responsible for identifying, assessing, and prioritizing security vulnerabilities within an organization's systems, networks, and applications. They use specialized tools to scan for vulnerabilities and analyze security data, then work with IT and security teams to recommend and implement mitigation strategies. In addition to technical analysis, they often help develop security policies, conduct risk assessments, and provide guidance on best practices. Their expertise helps protect the organization from cyber threats and ensures compliance with industry standards.
More about Senior Vulnerability Analyst jobs
What cities are hiring for Senior Vulnerability Analyst jobs? Cities with the most Senior Vulnerability Analyst job openings:
What are the most commonly searched types of Vulnerability Analyst jobs? The most popular types of Vulnerability Analyst jobs are:
What states have the most Senior Vulnerability Analyst jobs? States with the most job openings for Senior Vulnerability Analyst jobs include:
What job categories do people searching Senior Vulnerability Analyst jobs look for? The top searched job categories for Senior Vulnerability Analyst jobs are:
Infographic showing various Senior Vulnerability Analyst job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 86% Full Time, 6% Part Time, and 7% Contract. Highlights an 81% Physical, 9% Hybrid, and 10% Remote job distribution, with an average salary of $102,527 per year, or $49.3 per hour.

Vulnerability Analyst

MSCCN

Oak Ridge, TN • On-site

Full-time

Medical, Dental, Vision, Retirement

Posted 23 days ago


Job description


Location: Oak Ridge, TN
Job Title: Vulnerability Analyst
Career Level From: Associate
Career Level To: Senior Specialist
Job Specialty: Cyber Security
What You'll Do
The Vulnerability Analyst is responsible for analyzing key data streams and interpreting threats, vulnerabilities, impacts, and likelihood of asset exposure. The aggregation of ingested data informs analysis with key identifiers to generate a holistic view of the enterprise and provide recommended mitigations and/or remediation of possible exploitable assets. The analyst also assists Vulnerability and Compliance Assessment Management with cyber analysis to support requested exception requests. Responsible for cybersecurity assessment/analysis and provides recommendations for Enterprise level systems and applications designs. Involved in a wide range of cybersecurity areas, including system architectures, firewalls, inspection and analysis tools, encryption components and networking architectures. Involved in security reporting and analysis to regulatory agencies.
POSITION DUTIES AND RESPONSBILBILITES
  • Identify systemic security issues based on the analysis of vulnerability and configuration data.
  • Share meaningful insights about the context of an organization's threat environment that improve its risk management posture.
  • Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, and non-repudiation).
  • Host/network access control mechanisms (e.g., access control list, capabilities lists).
  • Conduct vulnerability scans and recognizing vulnerabilities in security systems.
  • Assessing the robustness of security systems and designs.
  • Detecting host and network-based intrusions via intrusion detection technologies (e.g., Snort).
  • Ability to mimic threat behaviors.
  • Support penetration testing tools and techniques.
  • Use social engineering techniques. (e.g., phishing, baiting, tailgating, etc.).
  • Support network analysis tools to identify vulnerabilities. (e.g., fuzzing, nmap, etc.).
  • Review logs to identify evidence of past intrusions.
  • Conduct application vulnerability assessments.
  • Perform impact/risk assessments.
  • Develop insights about the context of an organization's threat environment.
  • Analyze organization's cyber defense policies and configurations and evaluate compliance with regulations and organizational directives.
  • Maintain knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
What You Can Expect
  • Meaningful work and unique opportunities to support missions vital to national and global security
  • Top-notch, dedicated colleagues
  • Generous pay and benefits with a stable organization
  • Career advancement and professional development programs
  • Work-life balance fostered through flexible work options and wellness initiatives

Certificates/Security Clearances/Other
Why Y-12?
You get #morethanajob. We encourage employees to achieve a healthy personal balance among home, work and the community. One of the ways we embrace work-life balance is by offering flexible work arrangements that provide alternatives to the traditional workweek, while still meeting business needs. Top talent and personal commitment mean more to our success than any other factors, so we reward our people with the kinds of benefits that make a positive difference in the quality of their lives. Benefits such as: medical plan, prescription drug plan, vision plan, dental plan, employer matched 401(k) savings plan, disability coverage, education reimbursement and many more. Want to stay healthy and fit but hate the cost of a gym membership? Take advantage of one of our onsite workout facilities and eat healthy in our onsite cafeterias. Much more than a workplace, at Y-12, you can build a career that lasts a lifetime.Notes
The minimum education and experience for the lowest career level in the job posting range are listed under Minimum Job Requirements. Successful candidates hired into a higher career level than the minimum in the range must meet the requirements listed in the job leveling charts for the career level into which they are being hired.
If a range of Career Levels is posted, i.e., Senior Associate to Senior Specialist, internal applicants already in one of the Career Levels would come across at their current Career Level. Internal applicants currently in a lower level Career Level would move to the lowest posted Career Level.
Requires a Q clearance; however all qualified candidates will be considered regardless of their current clearance status. The ability to obtain and maintain a Department of Energy Q clearance is required.
This position may require entry into the Material Access Areas (MAA) and participation in the Human Reliability Program (10 C.F.R. Part 712), which requires successful competition of a DOE counterintelligence evaluation and may include a counterintelligence-scope polygraph examination.
This position may be categorized as a "designated position" identified by 10 C.F.R. Part 709, requiring successful completion of a DOE counterintelligence evaluation that may include a counterintelligence-scope polygraph examination.
CNS is a drug-free workplace. Candidates accepting a job offer will be required to pass a pre-placement physical, drug screening and background investigation. As an employee, you may be required to receive and maintain a security clearance from the United States Department of Energy in order to meet eligibility requirements for access to sensitive information or matter. U.S. citizenship is a requirement for security clearance applicants. All employees are subject to being randomly selected for drug testing without advance notification.
CNS is an equal opportunity employer. All qualified applicants will receive consideration for employment based on merit and without regard to race, color, religion, sex, sexual orientation, national origin, protected veteran status or disability.
Additional Qualifications/Responsibilities
Minimum Job Requirements
  • Bachelor's degree in engineering/science/information technology discipline.
  • Master's degree in engineering/science/information technology discipline.
  • Eight or more years of education and/or relevant experience may be considered to satisfy educational and years-of-experience requirements for this posting.
Preferred Job Requirements
  • Knowledge of computer networking concepts and protocols, and network security methodologies.
  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of cybersecurity threats and vulnerabilities.
  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
  • Knowledge of cryptography and cryptographic key management concepts
  • Knowledge of cybersecurity specific operational impacts of cybersecurity lapses.
  • Knowledge of cybersecurity application vulnerabilities.
  • Knowledge of network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML).
  • Knowledge of how traffic flows across the network (e.g., Transmission Control Protocol [TCP] and Internet Protocol [IP], Open System Interconnection Model [OSI], Information Technology Infrastructure Library, current version [ITIL]).
  • Knowledge of programming language structures and logic.
  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).
  • Knowledge of systems diagnostic tools and fault identification techniques.
  • Knowledge of what constitutes a network attack and a network attack's relationship to both threats and vulnerabilities.
  • Knowledge of different classes of attacks (e.g., passive, active, insider, close-in, distribution attacks).
  • Knowledge of system administration, network, and operating system hardening techniques.
  • Knowledge of cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
  • Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
  • Knowledge of security models (e.g., Bell-LaPadula model, Biba integrity model, Clark-Wilson integrity model).
  • Knowledge of system administration concepts for operating systems such as but not limited to Unix/Linux, IOS, Android, and Windows operating systems.
  • Knowledge of packet-level analysis using appropriate tools (e.g., Wireshark, tcpdump).
  • Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.
  • Knowledge of penetration testing principles, tools, and techniques.
  • Knowledge of application Security Risks (e.g. Open Web Application Security Project Top 10 list)